Description
Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this vulnerability can result in takeover of Oracle Contracts. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Compromise and full control of Oracle Contracts
Action: Immediate Patch
AI Analysis

Impact

Oracle Contracts, part of Oracle E‑Business Suite, contains a vulnerability in the Internal Operations component. The flaw allows an attacker that already has high‑level privileges and can reach the system over HTTP to fully compromise the application. The weakness is an access control issue (CWE‑269) which invalidates the confidentiality, integrity and availability of Oracle Contracts, effectively granting the attacker full control and the ability to perform any action the legitimate privileged user could.

Affected Systems

Affected product: Oracle Contracts for Oracle E‑Business Suite, version 12.2.14 through 12.2.15. Vendor: Oracle Corporation.

Risk and Exploitability

The assessed CVSS score is 7.2, indicating high severity. The EPSS score of less than 1% suggests limited exploitation activity in the wild. The vulnerability is not currently listed in the CISA KEV catalog. The exploit requires the attacker to have high privileges and network access via HTTP. Attackers could remotely call the vulnerable internal operations interface to achieve full control of Oracle Contracts.

Generated by OpenCVE AI on September 20, 2026 at 07:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Contracts security patch or upgrade to a non‑affected version.
  • Restrict HTTP access to Oracle Contracts to trusted networks or limit it to authorized users only.
  • Ensure proper authentication and authorization controls, enforcing least privilege and disabling unnecessary services.

Generated by OpenCVE AI on September 20, 2026 at 07:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title High‑Privilege HTTP Remote Compromise in Oracle Contracts

Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title High-Privilege Oracle Contracts Vulnerability Exposed via HTTP
Weaknesses CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title High-Privilege Oracle Contracts Vulnerability Exposed via HTTP
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this vulnerability can result in takeover of Oracle Contracts. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle contracts
CPEs cpe:2.3:a:oracle:contracts:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle contracts
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Contracts
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:22.589Z

Reserved: 2026-08-31T15:40:57.362Z

Link: CVE-2026-83482

cve-icon Vulnrichment

Updated: 2026-09-17T12:58:07.931Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:55.917

Modified: 2026-09-17T14:17:45.293

Link: CVE-2026-83482

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management